Search CVE reports
61 – 70 of 32653 results
The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field,...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary...
1 affected package
hdf5
| Package | 26.04 LTS |
|---|---|
| hdf5 | Needs evaluation |
(An integer underflow was found in the popt library when formatting hel ...)
1 affected package
popt
| Package | 26.04 LTS |
|---|---|
| popt | Needs evaluation |
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
1 affected package
genetic
| Package | 26.04 LTS |
|---|---|
| genetic | Needs evaluation |
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the...
1 affected package
bolt
| Package | 26.04 LTS |
|---|---|
| bolt | Needs evaluation |
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating...
1 affected package
neutron
| Package | 26.04 LTS |
|---|---|
| neutron | Needs evaluation |
Not in release
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type:...
1 affected package
opensips
| Package | 26.04 LTS |
|---|---|
| opensips | Not in release |